Organisations can leak confidential info like sieves

This week, Amazon has said it is investigating suspected internal leaks of confidential data by its employees for bribes to remove fake reviews and other seller scams from its website. Confidential data can be a company’s most valuable asset, whether this is customer data, trade secrets or future developments which will bring significant updates once introduced.
confidential

This week, Amazon has said it is investigating suspected internal leaks of confidential data by its employees for bribes to remove fake reviews and other seller scams from its website. Contributor Alastair Brown, Chief Technological Officer -BrightHR.

Confidential data can be a company’s most valuable asset, whether this is customer data, trade secrets or future developments which will bring significant updates once introduced. Data leaks, however small, can affect a company’s bottom line and reduce customer confidence in the security of the business. Additionally, under the recent data protection changes, a leak of personal data can result in a costly penalty for the organisation.

Employees are legally obliged to not share their employer’s confidential data, even if this obligation isn’t expressly included within the employee’s contractual documentation. It is often useful to include such an express term so that employees are reminded of this obligation when they join the company, and this term can be referred back to when necessary. Confidentiality clauses are also important to include as post-termination covenants because, after employment ends, the confidentiality duty only applies to information which could be classed as a trade secret. Therefore, post-termination restrictions will need to be expressly included in contracts to protect a broader range of information after employment ends.

Data leaks can be taking place in your business through a variety of methods, for example, data may be intentionally leaked by staff or leaked through careless behaviour. In order to reduce the likelihood of employees leaking confidential data, all members of staff should receive training on handling company data. This training should cover areas such as careless talk, email use, data protection obligations and confidentiality outside of the workplace. Monitoring of areas such as workplace email accounts and internet use will help identify where leaks are taking place. To avoid breaching privacy rights, employees will need to be informed of how monitoring will take place, in advance of this occurring. Where the business is aware there is an unidentified data leak, they may wish to consider whether a confidential reporting line can be introduced to encourage internal reporting.

Where careless data leaks are identified, usually through email errors such as attaching the wrong document or emailing an unintended recipient, employers should consider how they can address this. It may be the case that employees are working without paying attention, and a reminder of the importance of securely emailing data will help address this. Alternatively, employees may require training on email software systems to ensure they understand how to use these properly.

Should it be identified that an employee is intentionally leaking data this needs to be addressed, without delay, through the formal disciplinary policy. Dependent on the circumstances, intentionally leaking data may be considered serious or gross misconduct by the employer. A reasonable investigation into the allegations will need to be conducted, with further consideration as to whether suspension of the employee is necessary to prevent further data leaks or if other measures to temporarily restrict access can be introduced. Once a formal disciplinary hearing has been conducted, a disciplinary sanction which is reasonable in all the circumstances can be imposed. Not only will this help prevent the particular employee leaking data in the future, it will also deter others from carrying out a similar action.


Receive more HR related news and content with our monthly Enewsletter (Ebrief)

Read more

Latest News

Read More

How volunteering and opportunity creation outshine traditional support methods

12 August 2025

Recruitment

11 August 2025

On 7 July 2025, the government published several amendments to the Employment Rights Bill (ERB), including provisions that address the use of NDAs....

Employee Engagement, Training

11 August 2025

Arwa Due-Gundersen, Senior Business Development Manager at Cambridge Advance Online, a division of the University of Cambridge Online, says employees shouldn’t feel like they have...

Newsletter

Receive the latest HR news and strategic content

Please note, as per the GDPR Legislation, we need to ensure you are ‘Opted In’ to receive updates from ‘theHRDIRECTOR’. We will NEVER sell, rent, share or give away your data to third parties. We only use it to send information about our products and updates within the HR space To see our Privacy Policy – click here

Latest HR Jobs

University of Plymouth – Human Resources – HR Operations and Business PartneringSalary: £39,906 to £46,049 per annum – Grade 7

UCL – Human Resources Salary: £43,981 to £52,586

Reporting directly to the GB HR Director, you’ll lead a talented team of 25 across HR Administration, Payroll, People Analytics & Systems,. Collaborate cross-functionally, working

Reporting directly to the GB HR Director, you’ll lead a talented team of 25 across HR Administration, Payroll, People Analytics & Systems,. As our Director

Read the latest digital issue of theHRDIRECTOR for FREE

Read the latest digital issue of theHRDIRECTOR for FREE